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DIT Structure 
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Object Class 
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Attribute Type 
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Attribute Syntax 
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dn: cn=managerrole, dc=dom, dc=ain 
objectclass: top 
objectclass: LDAPsubentry 
objectclass: nsRole 
objectclass: nsSimpleRole 
objectclass: nsManagedRole 
cn: managgerrole 

description: Manager Role within the Company 



PIG-? 



dn: uid=pointyhair, ou=people, dc=dom, dc=ain 
objectclass: top 
objectclass: person 
objectclass: inetorgperson 
uid: pointyhair 
gn: pointy 
sn: hair 

nsRoleDN: cn=managerrole, dc=dom, dc=ain 
description: Pointy Haired Manager 
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dn: cn= building12people, dc=dom, dc=ain 

objectclass: top 

objectclass: LDAPsubentry 

objectclass: nsRole 

objectclass: nsComplexRole 

objectclass: nsFilteredRole 

cn: building12people 

nsRoleFilter: building=12 

description: People who work in building 12 
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dn: cn=megamanagerrole, dc=dom, dc=ain 

objectclass: top 

objectclass: LDAPsubentry 

objectclass: nsRole 

objectclass: nsComplexRole 

objectclass: nsNestedRole 

cn: megamanaggerrole 

nsRoleDN: cn=managerrole, dc=dom, dc=ain 

nsRoleDN: cn=networkmanager, dc=dom, dc=ain 

description: Super Manager Role within the 
Company 



dn: cn=peonrole, dc=dom, dc=ain 
objectclass: top 
objectclass: LDAPsubentry 
objectclass: nsRole 
objectclass: nsComplexRole 
objectclass: nsEnumeratedRole 
objectclass: groupofuniquenames 
cn: peonrole 

groupmember: uid=dboreham, ou=people, dc=dom, dc=ain 
groupmember: uid=merrells, ou=people, dc=dom, dc=ain 
groupmember: uid=claire, ou=people, dc=dom, dc=ain 
description: Lowest of the Low Roles within the Company 




For each entry within scope, the 
computed attribute nsRole is calculated 






The computed attribute nsRole is 
examined to see if the role is present. 






This results in a 
possess the role. 


list of entries that 







The list is thereafter returned to a 
client. 
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Dn:cn=messaging_server_cos, ou=people, o=acme 
objectclass: top 
objectclass: LDAPSubentry 
objectclass: cosSuperDefinition 
objectclass: cosClassicDefinition 
cosTemplate 

Dn: cn=MailServerCOS, cn=LocalConfig, o=NetscapeRoot 
cosSpecifier: mailServiceClass 
cosAttribute: mailboxquota 
cosAttribute: maysendexternalmail 
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, cn=MailServerCOS, cn=LocalConfig, o=NetscapeRoot 



objectclass: top 
objectclass: mailserveruser 
objectclass: cosTemplate 
mailboxquota: 10000000 
maysendexternalmail: TRUE 



i=guest, cn=MailServerCOS, cn=LocalConfi g) o=NetscapeRoot 



objectclass: top 
objectclass: mailserveruser 
objectclass: cosTemplate 
mailboxquota: 1000000 
maysendexternalmail: FALSE 




dn: cn=messaging_server_cos, ou=people, o=acme 
objectclass: top 
objectclass: LDAPSubentry 
objectclass: cosSuperDefinition 
objectclass: cosPointerDefinition 
cosTemplateDn: ou=people, o=acme 
cosAttribute: facsimilieTelephoneNumber default 



dn: cn=messaging_server_cos, ou=people, o=acme 

objectclass: top 

objectclass: LDAPSubentry 

objectclass: cosSuperDefinition 

objectclass: coslndirectDefinition 

coslndirectSpecifier: manager 

cosAttribute: accountingCode 



